October Patch Tuesday: 61 bugs and one zero-day fixed
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-11771 +1 in the same advisory: …11779 | The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly handle DNS responses, aka "Windows Search Remote Code Execution Vulnerability". NVD description · AI analysis pending | 9.8 group max | 64% |
| — | ||
| CVE-2017-11826 | Memory Corruption RCE in Microsoft Office, Word, SharePoint and Office Web Apps Affected versions of Microsoft Office and related server products fail to properly handle objects in memory (CWE-119 memory corruption), allowing remote code execution. The flaw is triggered when a user opens a specially crafted document, for example a malicious Word file delivered by email, with an affected version of Word, Word Viewer, the Office Compatibility Pack, Office 2010, or an affected SharePoint / Office Web Apps / Office Online Server component; the CVSS vector (AV:L, UI:R) reflects this user-interaction requirement. A successful attacker runs arbitrary code in the context of the logged-in user, with high impact on confidentiality, integrity and availability (CVSS 3.1 base 7.8, high). Anyone running Word 2007/2010/2013/2016, Office 2010, Word Viewer, the Office Compatibility Pack, SharePoint Enterprise Server 2010 or SharePoint Server 2010 (including Word Automation Services), Office Web Apps Server 2010 and 2013, Office Web Applications, or Office Online Server is affected. The bug was addressed as an Office zero-day in Microsoft's October 2017 Patch Tuesday release, is listed in the CISA KEV catalog (added 2022-03-03, indicating exploitation in the wild; ransomware use unknown), and EPSS assigns an 81.3% probability of exploitation within 30 days (100th percentile). Do: Apply Microsoft's October 2017 Patch Tuesday security updates to all affected components, including the frequently missed Word Viewer and Office Compatibility Pack, across endpoints, SharePoint 2010 servers, and Office Web Apps/Office Online Server deployments (KEV required action: apply updates per vendor instructions). Until patched, treat unsolicited Word documents and attachments as untrusted and verify users' installed Office builds. Prioritize remediation given confirmed in-the-wild exploitation. | 7.8 | 81% | KEV PoC ×2 |
| masshundreds of millions of desktop Office/Word installations (Microsoft's Office installed base exceeded 1 billion users when the flaw was disclosed), plus tens… |
Full article441 words · extracted from helpnetsecurity.com · click to collapse
For its October Patch Tuesday, Microsoft has patched 61 vulnerabilities (27 of them critical) and one Office zero-day labeled as “important.”

The zero-day
The memory corruption zero-day vulnerability in Microsoft Office (CVE-2017-11826) is reported to be actively exploited in the wild.
“An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system,” Microsoft noted.
“Exploitation of the vulnerability requires that a user open a specially crafted file with an affected version of Microsoft Office software. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) containing a specially crafted file designed to exploit the vulnerability.
Needless to say, users should implement the offered security updates that plug it.
Other high-priority fixes
“Priority should also be given to CVE-2017-11771, which is a vulnerability in the Windows Search service,” noted Jimmy Graham, director of product management at Qualys.
“This is the fourth Patch Tuesday this year to feature a vulnerability in this service. As with the others, this vulnerability can be exploited remotely via SMB to take complete control of a system, and can impact both servers and workstations. While an exploit against this vulnerability can leverage SMB as an attack vector, this is not a vulnerability in SMB itself, and is not related to the recent SMB vulnerabilities leveraged by EternalBlue, WannaCry, and Petya.”
We’ve already written about the risks raised by the vulnerabilities in the Windows DNS client (CVE-2017-11779), which could be triggered via a malformed DNS response sent by an attacker who is on the same network as the victim (e.g. on a free Wi-Fi network). Enterprise admins and end users alike are encouraged to implement the patches provided as soon as possible.
A crtical vulnerability in certain Trusted Platform Module (TPM) chips has also been flagged.
“This vulnerability is in the TPM chip itself, and not in Windows, but could result in weak cryptographic keys,” Graham explained.
“These keys are used for BitLocker, Biometric auth, and other areas of Windows. The updates provide a workaround for the weak keys leveraging additional logging and an option to use software-derived keys. Full remediation requires a firmware update from the device manufacturer.”
SANS ISC has also provided a clear overview of the fixed vulnerabilities, which can come in handy to all sysadmins.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2017/10/11/patch-tuesday-october-2017/